Copyright © 2010, Juniper Networks, Inc.
Configure the following General Properties:
7.
For Name, enter 199 (name appears as vlan199).
For Zone, select vlan.
For IP Address/Netmask, enter 1.0.1.199/24.
Clear the Manageable check box.
In the interface navigation tree, select Service Options. Select Telnet, Ping, and
Web, and then click OK:
Configure zone firewall rules in a security policy for vsys music. First, create a rule that
8.
permits HTTP traffic from music-untrust to music trust:
For From zone, select music-untrust.
For Source Address, select any.
For To zone, select music-trust.
For Destination Address, select any.
For Service, select HTTP.
For Action, select Permit.
For Install On, right-click and select Select Target. In the Select Target Devices list,
select vsys music, and then click OK.
Create a rule that denies all traffic from music-untrust to music trust:
9.
For From zone, select music-untrust.
For Source Address, select any.
For To zone, select music-trust.
For Destination Address, select any.
For Service, select any.
For Action, select deny.
For Install On, right-click and select Select Target. In the Select Target Devices list,
select vsys music, and then click OK.
Create a rule that permits all traffic from music-trust to music untrust:
10.
For From zone, select music-trust.
For Source Address, select any.
For To zone, select music-untrust.
For Destination Address, select any.
Chapter 8: Configuring VPNs
265
Need help?
Do you have a question about the NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 and is the answer not in the manual?